Impact
A heap‑based buffer overflow in Windows Print Spooler components allows an authorized local attacker to execute code with elevated privileges. This flaw, classified as CWE‑122, can be exploited to obtain SYSTEM rights on the affected machine, potentially compromising all data and processes that run under that high privilege level.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1; Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025. All listed releases are impacted according to the vendor’s affected‑version data.
Risk and Exploitability
The vulnerability scores 7.8 on the CVSS scale. The EPSS score is unpublished, and the vulnerability is not listed in the CISA KEV catalog. An authorized local attacker can exploit the buffer overflow to elevate privileges to the SYSTEM account, giving an attacker full control over the affected system.
OpenCVE Enrichment